discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack

ESET says OceanLotus used a FireAnt Metakit supply chain attack and a separate intrusion to push SPECTRALVIPER onto Vietnamese targets.

By Ravie Lakshmanan·Jun 11·thehackernews.com·2 min read

Intelligence analysis by GPT-5.4 Mini

ESET ties OceanLotus to two campaigns: one against a Vietnamese construction firm and another that abused FireAnt Metakit updates to infect stock investors. Both point to a more selective focus on domestic espionage and the use of SPECTRALVIPER as the main backdoor.

Why it matters

This shows a long-running APT shifting toward higher-value domestic targets and abusing trusted software update paths to reach them. It also highlights how weak update integrity can turn legitimate tools into malware delivery channels.

OceanLotus is like a burglar who sneaks in through a trusted delivery truck instead of breaking the door. In this case, it used a fake software update and hidden tricks to plant spying software on Vietnamese targets.

Analysis

What ESET found

ESET attributes two separate campaigns to OceanLotus, a Vietnam-aligned threat actor active since 2012. One campaign targeted an unnamed Vietnamese infrastructure and transport construction company from late 2024 through February 2026. The other abused FireAnt Metakit, a software platform used by Vietnamese stock investors, to deliver the SPECTRALVIPER backdoor between October 2025 and March 2026.

How the FireAnt attack worked

According to ESET, the attackers used the platform’s normal update path and a lack of signature validation to slip in a malicious setup.exe. After execution, the downloader collected basic host details and sent them to a staging server. From there, the attack used DLL side-loading: a legitimate binary loaded a rogue DLL, which then injected into OneDrive.Sync.Service.exe to launch SPECTRALVIPER.

The backdoor then reached out to a command-and-control server to send encrypted system information. ESET says it has not seen malicious updates through that channel since March 9, 2026, which may mean the campaign ended.

Separate intrusion, same backdoor

The second operation appears to have started with a public-facing Microsoft SQL server, possibly through remote code execution flaws. Once inside, the group kept access for more than a year and used SPECTRALVIPER in multiple variants across compromised hosts. ESET says the malware handled host profiling, lateral movement, and loading more payloads from the attacker’s infrastructure.

Bigger pattern

ESET says the evidence points to a shift in OceanLotus behavior: less emphasis on foreign espionage and more focus on domestic targets. The group has also been linked in the past to surveillance of civil society, media, and dissident targets, but this set of campaigns suggests a renewed concentration on Vietnamese organizations and investors.

Key points

  • ESET links OceanLotus to two campaigns using SPECTRALVIPER against Vietnamese targets.
  • One attack abused FireAnt Metakit updates to reach a small set of stock investors.
  • The update mechanism lacked signature validation, letting a malicious binary run as a legitimate update.
  • A separate intrusion may have started from a public Microsoft SQL server and stayed active for over a year.
  • ESET says the group appears to be focusing more on domestic espionage than foreign targets.
The Upside

If the findings lead vendors and users to tighten update signing and checks, it could close off a path the attackers relied on. Public exposure of the tactics may also help defenders spot SPECTRALVIPER activity faster and remove it before more systems are affected.

The Downside

The campaigns show that attackers can stay hidden for long periods and use trusted software channels to spread malware. If update integrity remains weak or public servers stay exposed, similar intrusions could keep reaching investors and domestic organizations.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycyber-espionagesupply-chain-attackmalwarevietnamtech

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 11, 2026

Source

thehackernews.com

Share

Topics

securitycyber-espionagesupply-chain-attackmalwarevietnamtech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…